Candidate: CVE-2013-4132 PublicDate: 2013-09-16 19:14:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4132 https://git.reviewboard.kde.org/r/111261/ Description: KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass. Ubuntu-Description: Notes: seth-arnold> NULL return from crypt() if the salt isn't sane mdeslaur> This is only an issue on glibc 2.17+, so precise and quantal mdeslaur> aren't affected. Also, our kde-workspace packages are compiled mdeslaur> with pam support, so they shouldn't be vulnerable. Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_kde-workspace: upstream: https://projects.kde.org/projects/kde/kde-workspace/repository/revisions/45b7f137fbc0b942fd2c9b4e8d8c1f0293e64ba7 upstream_kde-workspace: released (4.10.5) lucid_kde-workspace: DNE precise_kde-workspace: not-affected (older glibc) quantal_kde-workspace: not-affected (older glibc) raring_kde-workspace: not-affected (4:4.10.5-0ubuntu0.1) devel_kde-workspace: not-affected (4:4.10.90-0ubuntu2)